Skip to content
English - Australia
  • There are no suggestions because the search field is empty.

What MFA options does easyAML support?

Three options in order of preference: Passkey (phishing-resistant, biometric-based or PIN).

Overview

easyAML supports three MFA options, in order of preference: passkey, authenticator app (Google Authenticator, Microsoft Authenticator), and SMS one-time code. Email-based MFA is intentionally not offered - the email account is the password-reset channel, so using it as the second factor would mean an attacker with email access had both factors and the MFA layer would add no security. 

Comparing methods

  • Passkey - uses biometric authentication (Face ID, Touch ID) or a PIN on supported devices, or a hardware security key such as a YubiKey. Phishing-resistant, fastest day-to-day, no codes to type. Requires a supported modern device or hardware key.
  • Authenticator app - no telco dependency, works internationally. Officially supported apps are Google Authenticator and Microsoft Authenticator (as listed on the authenticator setup page). Other TOTP-compatible apps may work but are not officially supported.
  • SMS - familiar, no setup, supported for Australian numbers. Slowest and vulnerable to SIM-swap attacks; codes expire after 5 minutes. Note: a one-minute countdown on the SMS screen controls how soon a new code can be requested - this is separate from the code's 5-minute validity window.

Selecting your MFA type

Users can update their own MFA type after logging in. If a user cannot log in and needs their MFA method changed, contact easyAML support. To change this, go to your User Settings, click on Security and enable your 2FA option. 

International staff and offshore mobiles

Staff in locations not covered, or who prefer not to rely on SMS, should use an authenticator app or passkey, which work regardless of phone number or location. . To switch: open the user in the admin console, select "Authenticator App" or "Passkey" as the required method, and the user is prompted on next login to set it up (scan the QR code, or register a passkey). SMS MFA is then disabled for that user automatically.

To switch methods, see Change 2FA to Authenticator App.

Related articles